Services

Seven engagements. Senior-only delivery.


ISO 27001 Audit

Lead-auditor delivered, board-ready findings. Engaged via certification body or direct.

  • Stage 1 & Stage 2
  • Surveillance audits
  • Re-certification
  • Findings written for the room they'll be read in

Board Posture Assessment

An independent review of organisational information security posture — commissioned by directors, delivered to the board.

  • Strategic, operational, SDLC instruments
  • Maturity scored against a defined model
  • Prioritised options, not 47 recommendations
  • Board-pack ready on receipt
Read how we work →

ISMS

From zero to certifiable. We build the management system, you keep it — or we run it with you, co-sourced.

  • Policies & procedures
  • Risk methodology
  • Internal audit programme
  • Handover with templates and IP
Read how we work →

Penetration Testing

Coordinated pentest engagements with senior triage of every finding.

  • External & internal
  • Web application
  • Cloud & identity
  • Findings filtered for board signal

Essential Eight / IRAP

Maturity assessments aligned to Australian government baselines.

  • E8 maturity uplift
  • IRAP readiness
  • Hosting certification support
  • Pragmatic, not aspirational

Gap Assessment & Uplift

Where are you, where do you need to be, what's the shortest credible path.

  • ISO / SOC2 / NIST
  • Remediation roadmap
  • Quantified effort
  • No padding

Advisory & vCISO

Trusted counsel to boards and executives on cyber, AI and information governance. Strategy, not seat-warming.

  • Virtual / fractional CISO
  • AI governance & ISO 42001
  • Regulatory readiness — CPS 234, SOCI, Privacy Act
  • M&A due diligence on the deal clock
Read how we work →

Not sure which engagement fits? Tell us the decision you're trying to make and we'll tell you the smallest piece of work that gets you there.